Attacks on American companies have shifted from data theft to disrupting production.
Reuters has been tracking American companies that experienced breaches throughout 2026, and when viewed collectively, it provides greater insight than any individual case. The list includes companies like Nike, Coca-Cola, Novo Nordisk, and Abbott Laboratories, and very few occurrences involve the complex techniques that raised concerns following Google's discovery of an AI-developed zero-day vulnerability. Instead, the incidents frequently involve social engineering tactics, typically targeting third parties. Companies such as Carnival, Clover Health, iRhythm, and AdaptHealth fell victim to these tactics, often through contractor accounts rather than their own employees.
This represents a vulnerability that the industry has been slow to address, as it lies outside of any single organization's security perimeter. A supplier with access to your systems creates a security reliance that cannot be easily fixed, and attackers merely need to sound credible over the phone. One group that appears multiple times is ShinyHunters, which claimed to have acquired 80 million business records from Take-Two Interactive and Rockstar Games in April, and then breached Instructure’s Canvas platform in May, affecting nearly 9,000 institutions.
The latter incident holds more significance than the record numbers indicate. Canvas is a learning platform used by many American universities, so a single breach compromised student data across thousands of institutions that were not at fault. The healthcare and pharmaceutical sectors are more frequently impacted than any other, with companies such as Stryker, West Pharmaceutical Services, Novo Nordisk, iRhythm, AdaptHealth, and Abbott appearing on the list. This aligns with a trend indicating that medical data is both valuable and relatively poorly protected, as demonstrated by a separate breach this year exposing records for 1.8 million individuals, including fingerprints.
A key shift is from data theft to operational disruption. Stryker faced global disruptions in order processing, manufacturing, and shipping caused by a group linked to Iran, West Pharmaceutical reported system lockups halting its operations, Hasbro warned of fulfillment delays lasting weeks, and Coca-Cola’s fairlife division stopped production entirely. An attack that halts production is fundamentally different from one that merely copies a database, resulting in immediate financial losses and public consequences, which also explains why it typically demands a higher ransom.
Consumer brands often dominate headlines but provide limited insights. Nike had 1.4 terabytes of data published by a group called World Leaks, Wynn Resorts faced a ransom demand of about $1.5 million in bitcoin, and Crunchyroll lost eight million support records—each of these incidents is damaging, yet none lead to a halt in operations.
Some disclosures do not pertain to companies at all. A campaign against Fortinet compromised around 75,000 firewall and VPN devices globally, attacking the very tools organizations purchase to protect themselves. Nearly every disclosure includes a statement claiming no material impact on operations. This phrasing carries significant weight, as it pertains to securities-disclosure standards regarding financial materiality rather than an assurance that no one's data is up for sale.
Size does not guarantee safety and may not even be a relevant factor. Research reveals that mid-sized businesses suffer more from cybercrime than large or small ones, as they possess valuable assets yet lack the security budgets of multinational corporations.
The contrast with Europe offers valuable insights on attribution. The German industry association Bitkom, in collaboration with the country's domestic intelligence agency, attributes 46% of externally identified attacks to both Russia and China, while the American list is primarily filled with named criminal groups, with one notable exception linked to Iran. This discrepancy likely reflects more on who is making the attributions than the actual attackers. Criminal organizations publicize their exploits as part of their extortion methods, whereas state-sponsored operations are identified either by intelligence services or not at all.
The White House has established a coordination group focused on vulnerabilities identified by AI systems, though details on its functioning remain sparse. Whether this initiative will address a list heavily populated by attacks through contractor interactions is a valid inquiry, and one that the governance-first approach to security AI is at least beginning to consider.
Other articles
Attacks on American companies have shifted from data theft to disrupting production.
Reuters' ongoing count of corporate cyber attacks in the US for 2026 indicates that social engineering, contractor accounts, and healthcare targets are frequently involved.
